Im not sure if im missing something here, but from what I understand, what Apple is proposing is an enormous privacy boon that seems to be completely misunderstood. All cloud providers are required to, and do, make these scans. The proposal provides a way for them to comply with that requirement, but at the same time, allows them to completely lock themselves out of being able to decrypt your data in the cloud, excep…
There is NO end to end encryption being rolled out at the same time (so they can still decrypt and hand over your data in the cloud).
> This means they couldn't comply with a nation states demand to secretly decrypt your data, even if they were legally compelled too, unless they change how the cryptography at play here works.
Not only is this completely wrong (they can hand over your decrypted cloud data right now), it's wrong even going forwards with the assumption you made above about real E2EE (which we don't have...) - All they have to do is add a few hashes from that nation state to their catalog and your data is whisked away to apple for them to do with as they please (which right now is meaningless, since they currently have access to it anyways, but makes your point about E2EE a lot less compelling).